Zero-Day Exploit in Zimbra Used to Attack Brazilian Military via Malicious ICS Files
388/68 Tuesday, October 7, 2025 Cybersecurity researchers from StrikeReady Labs have uncovered an in-the-wild attack exploiting a Zero-Day vulnerability in Zimbra Collaboration, tracked as CVE-2025-27915 (CVSS 5.4), targeting the Brazilian military through malicious ICS calendar files. Attackers impersonated the Office of Protocol of the Libyan Navy and sent emails with weaponized ICS attachments. When opened, […]
